Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
60,142 detections
Filters
Last updated
All Time
Detection languages
23,200
16,896
4,280
4,077
3,289
Contributors
11,679
8,664
7,082
6,786
4,478
Categories
20,099
11,460
5,732
4,980
4,798
Platforms
39,723
6,855
6,349
4,079
3,510
Products / Services
10,351
9,601
6,991
4,335
3,859
MITRE Techniques
18,034
15,417
12,647
8,188
6,021
CVEs
68
68
58
56
50
IDS Classtypes
1,896
482
449
381
237
IDS Protocols
2,379
848
406
318
97
Detects high-volume credential brute-forcing activity targeting Dahua IP camera administrative interfaces (Ports 80/37777). The rule identifies a pattern of multiple connection failures across multiple distinct targets followed by a successful connection, which is highly characteristic of automated credential stuffing or password spraying attacks against embedded IoT devices.
This rule detects potential smishing or malvertising attacks by monitoring network activity for the download of .apk files from non-reputable domains. It correlates these download attempts with previous browsing behavior on URLs containing specific 'fake app-store' lure patterns (e.g., promotional text like 'Nexus One' or 'Download Now' outside of official marketplaces like Google Play, APKMirror, or APKPure).
Detects the execution of PowerShell via WScript or CScript scripts that contain command line arguments indicative of a file download cradle (e.g., Invoke-WebRequest, IWR, Net.WebClient, DownloadFile, DownloadString, or BITS transfer). This pattern is frequently used by adversaries to download and execute second-stage payloads or RMM agents.
Detects HTTP requests to Vercel deployment domains where the requested resource is a specific phishing kit asset ('font1.woff2'). This pattern is commonly associated with phishing campaigns hosted on free web hosting platforms.
Detects unauthorized processes, excluding standard web browsers, accessing sensitive browser files such as Login Data, Cookies, Web Data, and Local State. This activity is indicative of credential harvesting malware attempting to steal authentication cookies, saved passwords, or browser profiles.
Detects a malicious payload masquerading as a ClaudeDesktop installer that uses DLL sideloading via a tampered libcef.dll and a repurposed JetBrains binary to execute the SectopRAT .NET RAT.
This rule detects network activity and cloud API events indicative of an adversary utilizing the VAPI.ai platform to orchestrate automated voice-phishing (vishing) campaigns. It correlates outbound network connections to VAPI.ai endpoints with specific webhook callback patterns used to track call status for victim records.
Detects instances where rundll32.exe is used to invoke shell32.dll with the SHCreateLocal function, or where a web browser process (msedge.exe, chrome.exe, or firefox.exe) is spawned by rundll32.exe to open an HTML file. This pattern is often indicative of malicious activity such as HTML smuggling or local file execution attacks where rundll32 is used as a proxy to open files via the browser.
Detects the creation or presence of Windows Shortcut (LNK) files that use deceptive double extensions (e.g., .pdf.lnk) and specific filenames related to South Korean financial reporting, a technique associated with the threat actor Kimsuky to entice users into executing malicious code.
Detects network activity associated with the 'VPN-for-X' browser extension, specifically targeting communication with external services used for proxy configuration fetching and dead-drop proxy list retrieval. This includes TLS SNI checks for GitHub, Blogspot, and Telegram, as well as specific URI requests for proxy configurations and server lists.
Detects instances where a process spawns a child process using the exact same executable image path, specifically when the executable is located in user-writable directories such as Downloads or AppData\Local\Temp. This behavior is a common indicator of process hollowing or self-injection techniques used by malware, such as loaders that decrypt payloads in memory and then spawn a new, hollowed instance of themselves to execute the malicious code, frequently observed during post-exploitation activities.
Detects network traffic to specific domains (api.hhos.ru, mainapi.store) associated with the VPN-for-X browser extension's monetization API. This behavior is indicative of command-and-control or tracking communication identified as potentially malicious within the context of a browser extension.
Detects anomalous outbound HTTP/TLS requests to rutracker.org that contain a GUID-like identifier in the URI or deviate from normal user traffic patterns, which is characteristic of the 'VPN-for-X' browser extension acting as a command-and-control beacon.
Detects HTTP CONNECT requests to external networks that include Proxy-Authorization headers with Basic authentication. This pattern is indicative of malicious proxy tunneling or unauthorized credential usage for bypassing security controls or establishing command and control channels via a proxy.
Detects Microsoft Entra OAuth 2.0 device authorization grant flow completion immediately followed by non-interactive API access from automated user agents like python-requests. This behavior is indicative of device code phishing kits, where an attacker tricks a user into entering a code and then programmatically hijacks the resulting session token.
Detects network activity associated with the GhostCode phishing kit backend. The rule monitors for specific API endpoints used for credential and MFA harvesting, including loading configurations, geolocation, and polling for captured data, combined with specific session cookie identifiers.
Detects sign-in events using the OAuth 2.0 device code flow, which is a mechanism often abused in phishing campaigns (such as GhostCode) to lure users into authorizing malicious applications or granting access tokens without needing their actual credentials.
Detects suspicious non-interactive Entra ID sign-in events using the 'python-requests' User-Agent against sensitive Microsoft resources such as Microsoft Graph, Device Registration, or Intune. This activity is indicative of automated token abuse, particularly in the context of device-code phishing kits (e.g., GhostCode), where an attacker uses stolen session information to interact with Microsoft APIs.
Detects the Redis server process writing or modifying files within cron configuration directories. This is a common persistence technique used by attackers to gain recurring execution after exploiting vulnerable or misconfigured Redis instances.
KQL Query from file: Detect O365 Activities from OpenAI IP Addresses
Detects suspicious/unexpected usernames appearing in Cisco ISE access.log,
consistent with exploitation of CVE-2026-76460, an unauthenticated REST API
auth-bypass in Cisco ISE / ISE-PIC (CVSS 10.0, actively exploited, CISA KEV).
Cisco's own guidance is to hunt access.log for usernames not present in the
legitimate identity store; "dummyuser" is their published example artifact.
consistent with exploitation of CVE-2026-76460, an unauthenticated REST API
auth-bypass in Cisco ISE / ISE-PIC (CVSS 10.0, actively exploited, CISA KEV).
Cisco's own guidance is to hunt access.log for usernames not present in the
legitimate identity store; "dummyuser" is their published example artifact.



